Forge Forge
Home Terms

Privacy Policy

Last updated: August 9, 2026
The short version. Forge is a local-first Mac app with no Coursion backend. Your code, files, chats, and API keys stay on your Mac; we never receive your API keys or the content of your work, and we don't track you. Forge sends anonymous crash reports and feature-usage counts (you can turn both off in Settings). Beyond that, data leaves your Mac only where you direct it: requests to AI providers you configure, sites you open in the browser pane, optional iCloud sync through your own Apple account, and an update check to our website.

1. Who we are

Forge is a macOS application published by Coursion Studio ("Coursion", "we", "us"). This policy explains what Forge does with data. It applies to the Forge app and this website (forge.coursion.studio).

2. What Forge stores on your Mac

Everything Forge creates lives locally in your user folders — your projects on disk, workspace definitions, settings, notes, and chat transcripts (under ~/Library/Application Support/Forge and your own project folders). We have no server that holds a copy.

  • API keys are stored in the macOS Keychain and are never written to logs or sent anywhere except the AI provider endpoint they belong to.
  • Chat and terminal content stays on disk on your Mac.

3. Data that leaves your Mac (only when you direct it)

AI providers (bring your own key)

When you use an AI feature, Forge sends your prompt and the context you attach directly to the provider you configured — for example Anthropic, OpenAI, OpenRouter/Moonshot, or a local model via Ollama. Your key and prompt go straight to that provider over HTTPS; they do not pass through Coursion. Each provider's own privacy policy governs that data. If you run a local model (Ollama), that request never leaves your machine.

Browser pane

The built-in browser is a standard WebKit view. Sites you visit receive the same information any browser would send. We do not inject tracking or read your browsing.

Voice dictation (optional)

If you enable voice dictation, Forge uses Apple's Speech Recognition (SFSpeechRecognizer). Depending on your macOS configuration, audio may be sent to Apple for transcription under Apple's privacy policy. Forge does not store your audio and does not send it to Coursion. The microphone is used only while dictation is active.

iCloud sync (optional, off by default for keys)

If you turn on iCloud sync, Forge stores workspace definitions, settings, snippets, and (only if you explicitly enable it) API keys in your own iCloud account through Apple iCloud Drive and iCloud Keychain. This is Apple-to-your-devices sync governed by Apple's privacy policy — Coursion has no access to it and operates no sync server.

Software updates

Forge checks forge.coursion.studio for a signed update feed (via Sparkle). As with any web request, our static host may record standard server logs (such as IP address and app version) to deliver the update. We do not use this to build a profile of you.

Feedback & crash reports (only if you send them)

Forge can detect an unclean exit and locate the matching macOS crash report so you can send it to us. Nothing is transmitted automatically. If you choose to send feedback or a crash report, Forge composes an email in your mail client that you review and send yourself. It includes basic environment details (app version, macOS version, hardware summary) and no secrets. You decide whether to send it.

4. What we do not do

  • No ad SDKs, no third-party trackers, no advertising identifiers, no cross-app tracking.
  • No account or sign-up with Coursion is required to use Forge.
  • We never receive your API keys, source code, prompts, or file contents.
  • We do not sell or share personal data.

5. Crash reports & anonymous usage data

Forge sends two kinds of anonymous telemetry, both of which you can turn off in Settings (“Share anonymous usage & crash data”):

  • Crash reports — via Sentry (EU-hosted): app version and a technical stack trace when Forge crashes. Never your files, paths, prompts, or keys.
  • Usage counts — via PostHog (EU-hosted): anonymous events such as “a feature was used”, with the app version. Which feature, never what it ran on. No user profile is created and events are not linked to your identity.

6. Children

Forge is a developer tool not directed to children under 13, and we do not knowingly collect data from them.

7. Your choices

You control every outbound path: don't configure a provider key and no AI requests are made; leave iCloud sync off and nothing syncs; leave dictation off and the microphone is never used. You can delete Forge's local data by removing its Application Support folder and any keys from Keychain.

8. Changes

We may update this policy as Forge evolves. Material changes will be reflected here with a new "last updated" date, and where appropriate surfaced in the app.

9. Contact

Questions about privacy? Email hello@coursion.studio.

Home Privacy Terms Download
© 2026 Coursion · Made in SwiftUI